개인정보 처리방침
Privacy policy
서비스: 사이룸 / Sairoom · app.truecouple.android
운영자: JejuBucketList · 명정욱
개인정보 문의: db0192a@gmail.com
시행일: 2026년 9월 15일
1. 정보와 이용 목적
별명, 생성된 사용자 식별자, 대화 제목, 직접 입력한 이야기·감정·요청, AI 처리 동의, 요약, 선택한 행동, 이해받은 정도와 실천 체크인을 대화 제공·저장·복구에 사용합니다. 실명·이메일·전화번호·Google 로그인을 요구하지 않습니다. 불필요한 민감정보를 글에 입력하지 마세요. AI 신고에는 생성 결과, 사유와 선택 설명을 저장해 운영자가 검토합니다. 입력 원문은 신고에 별도로 첨부하지 않습니다. 이메일 문의에는 이메일 주소와 문의 내용이 포함됩니다.
2. 상대와의 공유
초대한 상대는 별명, 대화 제목, 작성·동의 상태, AI 요약, 합의·실천 상태를 봅니다. 원문을 그대로 보여 주지 않지만 요약에는 그 내용이 반영됩니다. 양측이 동의해야 AI에 전송합니다. 동의 철회는 이후 생성을 중지하며 이미 전송하거나 상대가 본 내용은 회수할 수 없습니다.
3. 사진과 기기 저장
선택한 사진은 Google ML Kit로 기기에서 문자 인식합니다. 사진 파일은 서버·AI에 업로드하지 않습니다. Google ML Kit는 기기·앱 버전, 설치 식별자, 성능·오류·기능 사용 메타데이터를 진단과 사용 통계 목적으로 HTTPS로 Google에 전송할 수 있습니다. 인식한 글이나 사진을 이러한 진단 데이터로 보내지 않습니다. Google의 개인정보 정책이 적용됩니다. 인식한 글은 확인·수정하고 직접 저장할 때 대화 내용으로 전송됩니다. 초안과 오늘의 메모는 기기에 암호화해 저장합니다. 연락처·위치·마이크 권한과 광고 식별자를 요구하지 않으며 광고·행동 분석 SDK와 개인정보 판매는 없습니다.
4. 처리업체와 국외 처리
Cloudflare, Inc.는 서버와 DB를 호스팅하며 암호화된 계정·대화·결과·신고 및 요청 IP 등 네트워크 정보를 처리합니다. 요청·저장 시 HTTPS로 전송합니다. D1은 APAC에 생성했으며 Cloudflare 글로벌 네트워크에서 국외 처리될 수 있습니다. 한국 내 처리만 보장하지 않습니다.
Groq, Inc.는 양측 동의 후 요청 시 이야기·감정·요청·제목을 HTTPS로 받아 AI를 생성합니다. 미국 사업자 서비스로 국외 처리될 수 있습니다. 별명·초대/복구 코드·인증 토큰·사진은 별도로 보내지 않습니다. 직접 글에 넣은 정보는 포함될 수 있습니다. 추론 미보관(ZDR) 설정을 사용하며 입력·출력 없는 이용 메타데이터는 업체가 보관합니다.
AI 동의를 거부·철회하면 AI 생성은 사용할 수 없습니다. 서버 저장을 원하지 않으면 대화 만들기·참여·저장을 사용하지 않고 예시나 기기 메모를 이용할 수 있습니다. 업체 안내와 문의: Cloudflare privacy, Groq data controls, Google ML Kit data disclosure, Google privacy.
5. 보안·보관·삭제
전송에는 HTTPS, 서버의 이름·대화·결과·신고에는 암호화를 적용합니다. 인증·초대·복구 코드는 해시로 저장합니다. 서버가 내용을 복호화할 수 있으므로 종단간 암호화는 아닙니다.
계정과 대화는 삭제할 때까지 보관합니다. 삭제 시 활성 DB에서 계정·참여 대화·관련 신고를 제거합니다. Cloudflare D1 자동 복구 기록에는 암호화된 이전 데이터가 최대 7일 남을 수 있습니다. 개인정보가 담긴 별도 상시 백업·신고 사본을 만드는 것은 기본 운영 방식이 아닙니다. 장애 복구 시 삭제 요청을 반영한 뒤 서비스를 다시 엽니다.
남용 방지용 주소·사용자 식별자의 해시와 요청 횟수도 저장합니다. 만료 카운터는 유효한 가입 요청마다 최대 100개씩, 7일보다 오래된 일일 할당량 기록과 함께 정리합니다. 정리 요청이 없으면 제거가 지연될 수 있습니다. 앱 원문 로그와 Workers 관측 로그 저장은 비활성화했습니다. 업체의 보안·서비스 메타데이터는 업체 정책을 따릅니다. 지원 이메일은 문의 해결 후 30일 내 제거하는 운영 기준을 적용하며 법적 보관 의무가 있으면 사유와 기간을 안내합니다.
6. 권리 행사
앱에서 기록 조회·수정, AI 동의 철회, 설정 → ‘내 데이터 모두 삭제’를 할 수 있습니다. 참여 공유 대화는 상대 기록에서도 삭제됩니다. 웹 삭제 페이지는 복구 코드나 로그인 키로 서버 데이터를 삭제합니다. 웹 삭제 후 기기 메모는 앱 데이터 삭제로 별도 제거하세요. 연결된 기기와 코드가 모두 없으면 소유권 확인이 제한됩니다. 문의는 db0192a@gmail.com로 보내고 복구 코드나 민감한 원문을 이메일에 넣지 마세요.
로그인 키 선택 기능
반복 로그인에 쓰는 43자리 키를 선택하여 만들 수 있습니다. 서버에는 키의 해시만 보관합니다. 새 키 발급·키 해제·계정 삭제·일회용 복구 시 이전 키가 무효가 됩니다. 키 로그인은 이전 기기 연결과 이전 복구 코드를 해제합니다. 키를 비밀번호처럼 보관하고 공유하지 마세요.
7. 연령과 변경
만 18세 이상을 대상으로 하며 아동 대상 서비스가 아닙니다. 변경 시 시행일을 갱신하고 중요한 변경은 앱에서 안내합니다.
English privacy policy
Sairoom (app.truecouple.android) is operated by JejuBucketList · 명정욱. Privacy contact: db0192a@gmail.com. Effective September 5, 2026. Intended for adults 18+.
Information and purpose
We process display names, generated account IDs, conversation titles, entries, feelings, needs, AI consent, summaries, selected plans and check-ins to provide, save and restore conversations. No real name, email, phone or social login is required. Avoid unnecessary sensitive information. Reports include the AI result, reason and optional explanation for operator review, without separately attaching original entries. Email support includes your address and inquiry.
Sharing and device processing
Your invited partner sees your name, shared title, submission/consent status, summaries and agreement/check-in status. Original entries are not displayed directly but summaries can reflect them. Both must consent before AI processing. Withdrawal stops future generation and cannot recall transmitted or viewed information. Google ML Kit recognizes image text on your device. Images are not uploaded; recognized text is sent only when you choose to save it. Google ML Kit can send device/app information, per-installation identifiers, performance, error and feature-use metadata to Google over HTTPS for diagnostics and usage analytics. This diagnostic data does not include recognized text or image content. Google privacy policies apply. Drafts and daily notes are encrypted locally. We do not request contacts, location or microphone permission, collect advertising IDs, sell data or use ad/behavioral analytics SDKs.
Providers and international processing
Cloudflare, Inc. hosts the server and encrypted database and handles network information such as IP addresses over HTTPS. D1 was created in APAC; Cloudflare's global network may process requests internationally. Korea-only processing is not guaranteed. Groq, Inc., a US provider, receives both entries, feelings, needs and title over HTTPS upon a jointly consented AI request. We do not separately send names, credentials, invitation/recovery codes or images; information typed into entries may be included. Inference Zero Data Retention is enabled. Groq retains usage metadata that excludes input/output content. See the provider privacy/data links above. You can decline or withdraw AI consent; generation will be unavailable. To avoid server storage, use the example or local reflection without creating, joining or saving a conversation.
Security and retention
Traffic uses HTTPS. Names, conversations, results and reports are encrypted on the server; credentials/codes are hashed. The server can decrypt content; this is not end-to-end encryption. Records remain until deletion. Deletion removes the account, shared conversations and reports from the active database; encrypted recovery history may persist in Cloudflare D1 for up to seven days. Separate ongoing personal-data backups or report copies are not the default process. After disaster recovery, deletion requests must be reapplied before reopening service. Expired abuse counters are pruned in batches of up to 100 on valid registration, together with daily quota records older than seven days; cleanup may be delayed without these requests. Content logging and Workers observability are disabled. Provider security/service metadata follows provider policies. Support email is removed within 30 days after resolution under the operating procedure, unless legal retention is required.
Optional reusable sign-in keys
You may create a 43-character sign-in key; only its hash is stored on the server. It remains reusable until replaced, revoked, account deletion or one-time recovery. Signing in disconnects the previous device and invalidates its recovery code. Treat the key as a password; never share it.
Your choices
View/edit entries, withdraw consent, or use Settings → Delete all my data. Shared conversations disappear from both participants' journals. The external deletion page accepts a saved recovery code or sign-in key to delete server data; clear local notes separately in device/app settings. Ownership verification is limited without a connected device or recovery code. Contact db0192a@gmail.com for privacy requests; do not email codes or sensitive entries. Material policy changes are announced in the app and reflected in the effective date.
관리자 시뮬레이션
허가된 운영자만 별도 시뮬레이션에서 두 관점을 직접 입력할 수 있습니다. 이 경로는 일반 회원의 대화나 상대 동의를 대신하지 않으며 다른 회원의 원문을 조회하지 않습니다. 입력과 마지막 결과는 관리자 기기에 암호화해 보관하고 초기화 또는 계정 전환 시 지웁니다. 분석 시 Groq에 전송하며 앱 서버에는 시뮬레이션 원문과 결과를 영구 저장하지 않습니다. 운영용 사용량·단기 요청 잠금은 처리하며 일반 서비스와 같은 무료 한도를 사용합니다.
Authorized administrators can enter both perspectives in a separate simulation. This does not act on member conversations, grant access to other users' original entries, or replace their consent. Inputs and the latest result are encrypted on the administrator's device and removed on reset or account change. Analysis sends them to Groq; the app server does not persist simulation inputs or outputs. Operational usage counters and short-lived request locks are processed, and the same shared free budget applies.